A 9.8-severity hole in industrial email code puts water and energy gear at risk
A buffer overflow in the lwIP SMTP client could let an unauthenticated attacker crash or hijack equipment running in energy and water systems. A patch is available.

Key points
- CISA published an advisory on 6 October 2026 for a critical flaw, CVE-2026-15340, in the Savannah lwIP SMTP client version 2.2.1, used inside industrial equipment at energy and water sites worldwide.
- The bug scores 9.8 out of 10 on the CVSS 3.1 severity scale, and in the worst case lets a network attacker take control of the device with no credentials and no user action required.
- Security firm xchglabs found the bug, reported it privately to Savannah, and the maintainers released patch_125_smtp_txbuf.diff, available as git commit 614420f, before disclosure.
- CISA tells operators to keep control systems off the public internet, isolate them behind firewalls, and use an up-to-date VPN for any remote access.
- The real distribution problem is that the fix exists upstream in a library; every device maker has to ship a firmware build before it reaches kit sitting in a water treatment plant.
A small piece of email-sending code buried inside a lot of industrial gear has a serious hole in it, and CISA wants operators to act now.
The software is the lwIP SMTP client: the thin layer of code that lets an embedded device send an automated email, the kind that says "pump failed" or "tank full". It's maintained on Savannah, a free-software hosting site, and gets compiled into controllers, gateways and sensors deployed across factories, substations and water plants.
CISA's advisory, published 6 October 2026, says version 2.2.1 doesn't check how large an incoming data block is before copying it into memory. That's a classic buffer overflow, the kind of bug that's been causing crashes and takeovers in networked software for three decades.
What could an attacker actually do?
Crash the device or run arbitrary code on it. CVE-2026-15340 scores 9.8 out of 10 under CVSS 3.1 and 9.3 under CVSS 4.0, both critical. No login, no click, no physical access. A controller sending status emails from a pumping station could be knocked offline or turned quietly into a foothold on the operations network. CISA flags deployments as worldwide, across energy and water sectors, from a vendor headquartered in Sweden.
We've been tracking the pressure on exactly these sectors: on 24 September we reported that a joint FBI-CISA fact sheet was asking water, power and manufacturing operators to lock down outside engineers who run their control systems. A remotely exploitable bug in commodity embedded code makes that advice land harder.
Is there a fix?
Yes, but getting it onto kit in the field is the hard part. The maintainers released patch_125_smtp_txbuf.diff, available as git commit 614420f82c8729d070e01464c0dddb3c9525c772, after xchglabs reported the issue privately and held disclosure until the fix was out. That's the upstream half done.
The downstream half is messier. LwIP is a library, not a product with a vendor portal and an auto-update channel. The patch has to travel through device makers before it reaches firmware, and firmware has to reach the field. Some of that gear is running software years behind current.
What should operators do now?
| Item | Detail |
|---|---|
| CVE | CVE-2026-15340 |
| Affected | Savannah lwIP SMTP client 2.2.1 |
| Severity | 9.8 critical (CVSS 3.1), 9.3 critical (CVSS 4.0) |
| Fix | patch_125_smtp_txbuf.diff, git commit 614420f |
| Advisory date | 6 October 2026 |
| Sectors flagged | Energy, Water and Wastewater |
CISA's standing guidance applies: keep control systems off the public internet, put them behind a firewall separate from the office network, and route remote access through a VPN that's kept current. CISA's own reminder is worth repeating here: a VPN is only as secure as the device on the other end of it.
The one concrete step worth doing this week: ask your device vendor, in writing, which lwIP version ships in the firmware and when a build containing commit 614420f will be available. If they can't answer that quickly, that's useful information too.



